CVE-2023-23765
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
30/08/2023
Last modified:
05/09/2023
Description
An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff in a re-opened Pull Request. To exploit this vulnerability, an attacker would need write access to the repository. This vulnerability was reported via the GitHub Bug Bounty Program https://bounty.github.com/ .<br />
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:* | 3.6.0 (including) | 3.6.16 (excluding) |
| cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:* | 3.7.0 (including) | 3.7.13 (excluding) |
| cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:* | 3.8.0 (including) | 3.8.6 (excluding) |
| cpe:2.3:a:github:enterprise_server:3.9.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://docs.github.com/en/enterprise-server@3.6/admin/release-notes#3.6.16
- https://docs.github.com/en/enterprise-server@3.7/admin/release-notes#3.7.13
- https://docs.github.com/en/enterprise-server@3.8/admin/release-notes#3.8.9
- https://docs.github.com/en/enterprise-server@3.9/admin/release-notes#3.9.1



